Get a free website with any plan

See how
CLOUDFLARE

Cloudflare 520 to 526 errors explained

Last updated

IN SHORT

Cloudflare 520 to 526 errors mean Cloudflare cannot get a valid response from your Flashcloud origin server. These errors only appear when the Cloudflare proxy is active. The fix almost always lives on your hosting server: verify your server is running, check your SSL certificate status, and match your portal's SSL/TLS mode to your server setup.

Cloudflare 520 through 526 errors mean Cloudflare could not get a valid response from your origin server, not that your site is broken in a way visitors would see without Cloudflare in front of it. The fix is almost always in your hosting, not in Cloudflare itself: check that your server is up, that SSL is issued and valid, and that the SSL/TLS mode on the Cloudflare CDN page matches what your server actually supports.

These errors only show up on domains with the Cloudflare proxy turned on. If you manage Cloudflare settings for a domain, you do it from your portal's Cloudflare CDN page (under Goodies), not a cloudflare.com dashboard. There is no separate Cloudflare account to log into.

What each error code means

Cloudflare uses 520 to 526 to distinguish where in the connection things broke down:

  • 520 Web server returned an unknown error: your server sent back something Cloudflare couldn't parse, often an empty response or a malformed header. Usually a crashed PHP process or a misconfigured redirect.
  • 521 Web server is down: Cloudflare could reach your server's IP but got no response on the web port at all. The server or web service is stopped.
  • 522 Connection timed out: Cloudflare tried to connect and got no reply in time. Common with an overloaded server or a firewall silently dropping Cloudflare's connection instead of rejecting it.
  • 523 Origin is unreachable: Cloudflare can't route to your server's IP at all. This points at DNS or network-level problems, not the web server itself.
  • 524 A timeout occurred: Cloudflare connected fine, but your server took too long to finish sending the response. A slow database query or a script stuck in a loop is the usual cause.
  • 525 SSL handshake failed: Cloudflare and your server couldn't agree on SSL, usually because your server has no valid certificate or the connection was closed mid-handshake.
  • 526 Invalid SSL certificate: your server presented a certificate Cloudflare doesn't trust, most often expired, self-signed, or for the wrong domain, combined with a SSL/TLS mode of Full (strict).

Why the number matters

520 to 524 are connection-level problems: your server is slow, down, or unreachable. 525 and 526 are certificate problems specifically. Knowing which bucket you're in tells you whether to look at server health or at SSL first, instead of guessing.

Fix 525 and 526 first: check SSL/TLS mode

Most 525/526 errors trace back to a mismatch between your Cloudflare SSL/TLS mode and your server's actual certificate. Open the Cloudflare CDN page for the domain in your portal and check the mode:

  • Full (strict) requires your server to present a valid, trusted certificate for that exact domain. If your certificate hasn't finished issuing yet, or DNS was only just pointed at us, this mode will throw 526 until the certificate catches up.
  • Full encrypts the connection to your server but doesn't validate the certificate, which tolerates a self-signed or mismatched cert temporarily.
  • Flexible only encrypts the visitor-to-Cloudflare leg, not Cloudflare-to-server. It shouldn't cause 525/526 by itself, but it's the wrong long-term setting for a hosted domain with a working certificate.

Free Let's Encrypt SSL is auto-issued once DNS points to us, typically within about 5 minutes, and renews automatically after that. If you just pointed a domain at us or just enabled the Cloudflare proxy, give the certificate a few minutes to issue before assuming something is broken. If it's been longer than that and you're still seeing 525/526, Full (strict) combined with a certificate that hasn't issued yet is the most common cause; temporarily switching to Full confirms the diagnosis, then switch back to Full (strict) once the certificate is in place. For the full rundown of every toggle on that page, see every Cloudflare setting explained.

Fix 520 to 524: check the server, not Cloudflare

These codes mean the problem is between Cloudflare and your origin, so start on the server side:

  1. Check whether the site loads directly, without Cloudflare in the way, by temporarily turning off the Proxy toggle on the Cloudflare CDN page for that domain. If it loads fine with the proxy off, the server itself is healthy and the issue is specific to the Cloudflare connection (often SSL mode, covered above).
  2. If the site is slow or unresponsive even with the proxy off, check Metrics → Errors in cPanel for the domain. A flood of PHP fatal errors or a crashed process usually explains a 520 or 522. See getting around cPanel: the tools that matter for where that log lives.
  3. For a 524 specifically, look at what's slow: a plugin doing a heavy database query, an API call with no timeout, or a script stuck waiting. The fix has to happen on your server, by finding and speeding up the slow operation.
  4. For a 523, confirm DNS is actually pointing at your hosting. Check the records on the DNS Zone Editor for the hosting service (Services → your hosting → DNS Zone Editor), not the Domains → DNS page, which only controls nameservers.

Turning the proxy off as a diagnostic, not a fix

Turning off the Proxy toggle removes Cloudflare from the path entirely, which is useful for confirming whether the problem is your server or the Cloudflare layer, but it also removes caching, the CDN, and Cloudflare's protection while it's off. Treat it as a temporary test, and turn it back on once you've identified the real cause.

When to open a ticket

If you've confirmed the server responds fine with the proxy off, the certificate has had time to issue, and you're still seeing 520 to 526 errors with the proxy on, open a ticket from Support → New ticket in the portal. Include which error code you're seeing, the domain, and whether it's constant or intermittent so support can investigate.

Common questions

Why am I seeing error 525 or 526 on my site?

Your SSL certificate is likely still issuing or your SSL/TLS mode is set too strictly. Free Let's Encrypt SSL auto-issues within about five minutes of pointing DNS. Temporarily change your SSL/TLS mode from Full (strict) to Full in the portal until the certificate is active.

How do I check if the problem is my server or Cloudflare?

Temporarily turn off the Proxy toggle on your portal's Cloudflare CDN page. If the site loads with the proxy off, your origin server is fine and the issue involves your Cloudflare connection. If the site still fails, check Metrics then Errors in cPanel to find crashed processes or PHP errors.

Where do I log in to change my Cloudflare settings?

You manage all settings from the Cloudflare CDN page under Goodies in your portal. You do not have a separate cloudflare.com account or dashboard.

Why does my site return error 524?

Your server took too long to send back the response. Common causes include slow database queries, API calls without timeouts, or scripts stuck in loops. You need to identify and speed up the slow process on your hosting server.

CAN'T FIND IT?

Real humans answer fast.

Hosting with us? Open a ticket and a real person replies - no scripts, no upsells. Still choosing a host? The same team is included with every plan, from day one.